Skip to content

fix(token): don't panic on static JWTs without exp - #16

Merged
bonifaido merged 3 commits into
mainfrom
fix/static-token-no-exp
Sep 30, 2026
Merged

bonifaido merged 3 commits into
mainfrom
fix/static-token-no-exp

Conversation

@bonifaido

Copy link
Copy Markdown
Member

StaticIdentityTokenProvider dereferenced the result of GetExpirationTime, which is nil when a JWT has no exp claim. Such tokens now come back with a zero ExpiresAt, which the other providers already treat as never expiring. Adds tests for the provider.

GetExpirationTime returns nil when the exp claim is absent, which
StaticIdentityTokenProvider then dereferenced. Treat such tokens as
never expiring, matching how the other providers handle a zero
ExpiresAt.
@bonifaido
bonifaido requested review from stoader and a balanced review from Copilot and removed request for stoader September 30, 2026 11:53
@bonifaido bonifaido self-assigned this Sep 30, 2026
@bonifaido bonifaido added the bug Something isn't working label Sep 30, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The nil dereference is correctly prevented and the affected behavior has focused test coverage.

Review effort: Balanced
Findings: None

What changed in this PR

Prevents static JWTs without an exp claim from panicking by treating them as non-expiring.

Changes:

  • Safely maps a missing expiration claim to zero ExpiresAt.
  • Adds tests for expiring, non-expiring, and malformed tokens.
File Description
pkg/​token/​static_token_provider.go Handles absent JWT expiration claims safely.
pkg/​token/​static_token_provider_test.go Tests static token parsing and expiration behavior.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@bonifaido
bonifaido merged commit 632e3e0 into main Sep 30, 2026
1 check passed
@bonifaido
bonifaido deleted the fix/static-token-no-exp branch September 30, 2026 12:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants